Open
Description
CVE-2021-23441 flagged here:
Description
All versions of package com.jsoniter:jsoniter are vulnerable to Deserialization of Untrusted Data via malicious JSON strings. This may lead to a Denial of Service, and in certain cases, code execution.
References
https://nvd.nist.gov/vuln/detail/CVE-2021-23441
https://snyk.io/vuln/SNYK-JAVA-COMJSONITER-1316198
Does somebody have a patch/fix for this that could be merged and then released? Any help would be much appreciated!
Metadata
Metadata
Assignees
Labels
No labels